Network Packet Spoofing Vulnerability in GRE and GRE6 Protocols by IETF
CVE-2024-7595

6.5MEDIUM

Key Information:

Vendor
Ietf
Status
Rfc2784 - Generic Routing Encapsulation (gre)
Vendor
CVE Published:
5 February 2025

Summary

The GRE and GRE6 Protocols allow an attacker to exploit a weakness in the source validation of network packets. This lack of proper validation can lead to the spoofing of packets and unauthorized routing of network traffic through an exposed interface. As a result, this vulnerability may enable various network security issues including access control bypass and unexpected behaviors in network communication.

Affected Version(s)

RFC2784 - Generic Routing Encapsulation (GRE) STD 1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.